import "hash" rule bulwark_https_bulwarkblack_com_xworm_rat_campaign_exploits_cve_2018_0802_in_multi_language_phish { meta: author = "Bulwark Black LLC" source = "https://bulwarkblack.com/xworm-rat-campaign-exploits-cve-2018-0802-in-multi-language-phishing-attacks-using-fileless-injection/" description = "Auto-extracted indicators. Verify before use; not a behavioral detection rule." generated = "2026-08-27T00:00:00Z" tlp = "TLP:CLEAR" indicator_count = "17" strings: $s0 = "berlin101.com" ascii wide nocase // Domains $s1 = "cloudinary.com" ascii wide nocase // Domains $s2 = "pub-3bc1de741f8149f49bdbafa703067f24.r2.dev" ascii wide nocase // Domains $s3 = "r2.dev" ascii wide nocase // Domains $s4 = "res.cloudinary.com" ascii wide nocase // Domains $s5 = "retrodayaengineering.icu" ascii wide nocase // Domains $s6 = "http://pub-3bc1de741f8149f49bdbafa703067f24.r2.dev/wwa.txt" ascii wide nocase // URLs $s7 = "https://pub-3bc1de741f8149f49bdbafa703067f24.r2.dev/wwa.txt" ascii wide nocase // URLs $s8 = "https://res.cloudinary.com/dbjtzqp4q/image/upload/v1767455040/" ascii wide nocase // URLs $s9 = "https://res.cloudinary.com/dbjtzqp4q/image/upload/v1767455040/optimized_MSI_lpsd9p.jpg" ascii wide nocase // URLs $s10 = "https://retrodayaengineering.icu/HGG.hta" ascii wide nocase // URLs condition: any of ($s*) or hash.md5(0, filesize) == "3bc1de741f8149f49bdbafa703067f24" or hash.sha256(0, filesize) == "3f4c3c16f63fb90d1fd64b031d8a9803035f3cb18332e198850896881fb42fe5" or hash.sha256(0, filesize) == "8665bc1b33cbe6f5859cd6e362af77738ba73a6e6d4b9974c16c8521d84c1892" or hash.sha256(0, filesize) == "eacd8e95ead3ffe2c225768ef6f85672c4bfdf61655ed697b97f598203ef2cf6" or hash.sha256(0, filesize) == "ee663d016894d44c69b1fdc9d2a5be02f028a56fc22b694ff7c1dacb2bbbcc6d" or hash.sha256(0, filesize) == "fd9ba9e6bd4886edc1123d4074d0eac363df61162364530b1303390aa621140b" }